Fine Tracker.

A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.

5,273 entries

Total fines
€8.6bn
Decisions
5,273
Jurisdictions
33
Regulators
74
Avg monthly
€162.7m
YoY volume
-21%
Country
Type
Date range
ImposedCompanyCountryAuthorityTypeAmount
12 May 2022Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided.ITGaranteGDPR€3,000
16 May 2012CONFORAMA ESPAÑA S.A.CONFORAMA ESPAÑA S.A. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited advertising SMS messages to customers. The conduct breached Article 21 of the LSSI on marketing communications without prior consent.ESAEPDePrivacy€3,000
16 Nov 2022Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events.ROANSPDCPGDPR€3,000
18 Jun 2025SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure.FRCNILGDPR€3,000
31 Jan 2023PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules.ESAEPDGDPR€3,000
16 Dec 2022NORDETIA CLINICS IBERIA, S.L.NORDETIA CLINICS IBERIA, S.L. was fined 3,000 EUR by the AEPD. The authority found that the company obstructed an inspection by failing to provide access required under Article 58(1) GDPR.ESAEPDGDPR€3,000
23 Mar 2023Tehnoplus Industry SRLANSPDCP imposed a fine of EUR 3,000 on Tehnoplus Industry SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements.ROANSPDCPGDPR€3,000
22 Jan 2022SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILESCNIL imposed a fine of 3,000 EUR on SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILES and issued an injunction under penalty. The case concerns a confirmed compliance breach.FRCNILGDPR€3,000
20 Feb 2021FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements.ESAEPDGDPR€3,000
16 Sept 2024Vodafone România SAVodafone România SA was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to respond to a request to exercise the GDPR rights of access and erasure.ROANSPDCPGDPR€3,000
12 Jul 2024CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients.ESAEPDGDPR€3,000
11 Sept 2025MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of 3,000 EUR on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure.FRCNILGDPR€3,000
24 Jun 2020MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified.ESAEPDGDPR€3,000
06 Mar 2023Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data.ROANSPDCPGDPR€3,000
26 Feb 2024VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details.ROANSPDCPGDPR€3,000
13 Feb 2015COMERCIAL POLINDUS, 21, S.L.COMERCIAL POLINDUS, 21, S.L. was fined by the AEPD 3,000 EUR for sending unsolicited commercial communications. The case concerned Article 21 of the LSSI, which prohibits such messages without prior recipient consent.ESAEPDePrivacy€3,000
18 Aug 2025SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach.ROANSPDCPGDPR€3,000
10 Sept 2021LODEJU, S.L.LODEJU, S.L. was fined EUR 3,000 by the AEPD for excessive video surveillance of public space without proper signage. The authority found a breach of GDPR Articles 5(1)(c) and 13.ESAEPDGDPR€3,000
11 Dec 2015EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L.EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L. was fined by the AEPD EUR 3,000 for sending commercial emails without the required consent. The authority found this conduct breached Article 21.2 of the LSSI.ESAEPDePrivacy€3,000
27 Dec 2022Kaufland România SCSKaufland România SCS was fined by ANSPDCP EUR 3,000 for GDPR violations. The investigation was completed in November 2022.ROANSPDCPGDPR€3,000